
Closed
Posted
Paid on delivery
URGENT – Magento 2 Security Incident Response / Malware Forensics / AWS We require an experienced Magento 2 / Adobe Commerce security specialist for an urgent production incident. Environment: Magento 2.4.3-p1 PHP 7.4 AWS EC2 Cloudflare ~30,000 products We have confirmed malicious JavaScript activity in production, including requests to: [login to view URL] and evidence of a suspicious checkout form submitting to: [login to view URL] Checkout has currently been restricted for customer protection. We need someone who can urgently: recover/establish secure SSH access through our AWS account if necessary; preserve forensic evidence before cleanup; identify the initial compromise and persistence mechanism; inspect Magento files, generated/static content, database/configuration, cron jobs, Admin/API access and server logs; identify all malicious files/code/configuration; clean the environment safely; rotate/revoke compromised access; harden Magento/server/Cloudflare; validate that checkout and storefront are clean before reopening; investigate recurring OOM/Varnish/PHP/MySQL/Elasticsearch performance incidents; provide a written technical report with findings, root cause and remediation. We are not looking for someone who simply deletes infected generated files or runs an antivirus scan. Root-cause and persistence analysis are mandatory. Please apply only if you have significant Magento 2 security/incident-response experience. Adobe Commerce/Magento certification, AWS experience and previous malware/card-skimmer investigations are strongly preferred. In your proposal, please provide: relevant Magento certifications; examples of similar Magento compromise investigations; AWS/Linux security experience; your immediate availability; your proposed first steps before making any changes to production.
Project ID: 40677181
71 proposals
Remote project
Active 4 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
71 freelancers are bidding on average €456 EUR for this job

Hello, As a seasoned developer with over 15 years of experience, I have encountered and successfully mitigated countless security incidents similar to the one you're experiencing with your Magento 2 platform. I understand the urgency of the matter and assure you that I will effectively and efficiently address this issue by leveraging my extensive knowledge and skills in Magento Commerce, AWS EC2, and Cloudflare. My mastery in identifying compromise, analyzing persistence mechanisms, and cleaning up malicious files while safeguarding crucial forensic evidence has been honed through years of working on diverse projects involving malware remediation. Additionally, my proficiency in PHP, Varnish, MySQL, and Elasticsearch will be vital as we investigate the recurring OOM/Varnish/PHP/MySQL/Elasticsearch performance incidents you mentioned. Most importantly, I don't believe in just eliminating the symptoms; my focus is on conducting a thorough root-cause analysis for a complete resolution. Upon completing this task, I will draw up a detailed, well-documented technical report highlighting the findings, the root cause behind the incident, and recommend appropriate remediation steps to prevent future occurrences. In conclusion, my certifications in Magento applications along with my demonstrated skills in AWS/Linux security could prove instrumental for your specific project demands. Let's work together to promptly clean your system leading Thanks!
€350 EUR in 6 days
8.6
8.6

Hi there I can sort out the issue for you and provide you more details how did it happen. Anyway since once it happened I suggest you to upgrade to the latest version since now they are aware to all of your vlunreabilities. Magento developer with 15 years of experience advise. Best Bojan
€700 EUR in 3 days
8.6
8.6

As an experienced Senior Full-Stack Web & eCommerce Developer with over a decade of expertise, I possess all the skills needed to tackle your urgent Magento security incident head-on. I am familiar with the entire Magento ecosystem including both Adobe Commerce/Magento and AWS, which will be invaluable in navigating your setup. In addition, I have ample experience working with large-scale databases like MySQL, PHP web development, as well as handling Web Security, making sure that no stone is left unturned during your project. I understand that in your situation, quick and effective action is essential. This is why my immediate availability will pair perfectly with my skillset and urgency for Cybersecurity matters. My first step would likely involve establishing secure SSH access through your AWS account, followed by preserving forensic evidence before cleaning up. I also guarantee investigation into OOM/Varnish/PHP/MySQL/Elasticsearch performance incidents to ensure that this is a one-off occurrence,
€250 EUR in 1 day
8.3
8.3

Having spent a decade in E-commerce engineering, I have garnered extensive experience building digital businesses rooted in Shopify (Liquid & Headless), WooCommerce, and various Custom PHP solutions much like your Magento 2 project. My technical prowess includes App integration for inventory management, shipping automation and – particularly valuable in this context – payment gateway security. I'd also like to draw your attention to my problem-solving capability. I'd not merely delete infected generated files or run generic antivirus scans but delve into the root cause of the issue and dissect the persistence mechanism as you specifically required. High speed and responsive design are hallmarks of my work which can prove beneficial in tackling OOM/Varnish/PHP/MySQL/Elasticsearch performance incidents. Now let me anticipate your next question: "What are the specific skills that make me the most suitable candidate on this platform?" Well, to begin with, I've impressed both users and employers on this platform having delivered every single project I've taken up to 5-star standards. Additionally, a perfect 100% completion record over 370 projects is no fluke – it speaks volumes about my reliability and competence.
€750 EUR in 2 days
8.2
8.2

As an experienced e-commerce specialist with a primary focus on Magento, I've developed substantial expertise in dealing and resolving incidents that revolve around platform security and malware removal. I understand the urgency of your current situation and the potential harm it can cause to your business. My skill set aligns perfectly with your project requirements; proven by the numerous instances where I've effectively managed similar Magento compromise investigations. Moreover, my understanding and experience with AWS/Linux aligns well with the project's environment, enabling me to securely establish SSH access and preserve crucial forensic evidence for detailed analysis. My effective detection methods will ensure that every malicious file/code/configuration is unearthed and safely expelled from your system, restoring peace of mind to you and your customers while providing robust measures to mitigate any chance of recurrence. Finally, my commitment to delivering premium solutions goes hand in hand with generating comprehensive reports based on findings for you, helping identify the root cause while providing effective remediation options. With my immediate availability and track record of efficient delivery, I assure you- we'll build stronger defenses against any future attacks. Let's restore and reinforce the security of your Magento 2 store together!
€500 EUR in 1 day
7.8
7.8

Hello!, I am a Florida-based senior software engineer and I’ve handled urgent security cleanup for compromised PHP and AWS-based applications before. For a Magento 2 card skimmer incident, the real issue is usually not just removing malware, but finding the entry point, stopping reinfection, and restoring checkout safely. My approach: 1. Contain fast, preserve evidence, and identify live skimmer code, backdoors, cron abuse, or modified files. 2. Audit Magento, PHP, MySQL, AWS, Cloudflare, and server logs to trace the attack path and scope. 3. Remove malicious code, rotate credentials/keys, patch vulnerable components, harden permissions, and verify the store is clean. 4. Test checkout, admin access, and payment flow, then set monitoring to prevent repeat compromise. I’m very detail-oriented with incident response, and that matters here because these cases are often “cleaned” incorrectly by people who miss the root cause. I focus on the fastest safe path back to production. Relevant work: - Magento 2 security cleanup for an apparel store after injected checkout JS - AWS-hosted PHP commerce app hardening and malware removal - Cloudflare-protected storefront incident review and reinfection fix - MySQL/PHP e-commerce recovery with log-based forensic analysis Quick questions: 1. Is the skimmer affecting checkout, admin, or both? 2. Do you have recent server snapshots/logs? 3.
€650 EUR in 2 days
6.7
6.7

With over 15 years in the eCommerce industry, I've dealt with a wide range of challenges, including incident response and malware forensics - making me the perfect fit for your urgent Magento 2 project. My Magento expertise, AWS experience, and proven track record in dealing with security incidents align seamlessly with your requirements. In line with your request, my process will be more than just removing infected files; I ensure root cause analysis and persistence identification to prevent future attacks because cybersecurity shouldn't be a one-time fix. My core skills span across Magento development, performance optimization, and web security - key elements for addressing issues of checkout restriction like yours, server logs investigation & analysis, Directory traversal prevention like OOM vulnerability issues you're noticing. In addition to that, my knowledge of cloud security and SSH access management will guarantee that your AWS environment is promptly secured as it was before. Moreover, not only do I build scalable architectures but I also prioritize clean codes and business-focused solutions. My goal isn't just to fix what's wrong but to deliver a stable environment designed to propel your growth. Let me leverage my vast experience and skill set to provide you with first-rate incident handling while maintaining peak performance for your online store.
€750 EUR in 3 days
6.9
6.9

Hi there, regarding your urgent Magento 2 security incident, I can help you establish secure SSH access through AWS and preserve forensic evidence efficiently. My experience with Magento 2 and AWS equips me to identify initial compromises while performing a thorough inspection of your server logs, files, and configurations. I possess relevant Magento certifications and have participated in several similar investigations. I am ready to start immediately and will ensure a structured approach to clean up the environment and strengthen your security measures effectively. Your satisfaction is my priority and I guarantee that I will deliver you a high-quality result. Regards, Ali
€250 EUR in 7 days
6.4
6.4

As an experienced Full-Stack Web Developer, my skills in incident response and malware forensics make me a perfect fit for your urgent project. I understand the gravity of the Magento 2 security breach you're facing, and I can assure you that I am well-equipped to tackle it head-on. My understanding of AWS EC2, Linux, and PHP is just what you need-not to mention my ability to deal with complex ecommerce platforms like Magento 2.4.3-p1. In similar challenging situations, I've proven my expertise in recovering secure SSH access through AWS accounts effectively. I understand the importance of preserving forensic evidence before cleanup, identifying compromise points and being thorough when inspecting files and logs for malicious code-qualities that you explicitly requested for this task. Please consider this pitch an immediate call to action! Fourge is readily available to apply its extensive competitiveness in pursuing your needs. Rest assured that not only will the job be completed satisfactorily but also promptly; timing is crucial in the face of such security threats.I'll initiate the investigation by conducting a full-system audit, identifying potential access points, analyzing logs and finally carrying out QR scans on potentially-infected generated files. I'm keen on providing a comprehensive root-cause analysis report with a demonstrable roadmap for remediation at the end
€500 EUR in 2 days
6.3
6.3

As a multi-faceted developer driven by agentic AI, I bring a distinctive skillset and extensive experience that perfectly aligns with the urgent needs of your project. I specialize in securing complex systems like Magento 2 / Adobe Commerce, AWS EC2, PHP and possess an intuitive understanding of card skimmer incident response. My work doesn't stop at superficial malware removal - I delve deep into root-cause analysis to ensure total eradication from your system. With a proven track record in AWS/Linux security, my ability to swiftly recover secure SSH access will save precious time for your business. Having led multiple investigations into similar Magento compromise incidents, my meticulous attention to detail will help identify the origin and persistence mechanism of the attack on your system.
€500 EUR in 7 days
6.1
6.1

With over a decade of experience in IT, focusing on server administration and security, I am confident in my ability to address your urgent Magento 2 security incident. I understand that simply removing malicious files isn't enough; identifying the root cause and means of persistence is crucial for a lasting solution. Moreover, your mention of recurring performance issues tells me there may be deeper underlying problems beyond the immediate malware threat that require a thorough investigation. In addition to my extensive Linux skills and aptitude with MySQL, I can employ my deep understanding of web security to perform tasks like establishing secure SSH access through your AWS account and scrutinizing crucial Magento files, generated/static content, database/configuration, cron jobs, Admin/API access as well as server logs. I bring not only technical proficiency but also prompt availability and fast response rate – both essential for an urgent situation such as this.
€500 EUR in 1 day
6.3
6.3

I have handled urgent Magento 2 card skimmer incidents before, including one with a similar attack vector involving injected JS and suspicious checkout endpoints. My first priority will be to secure AWS access immediately for controlled investigation, preserving all forensic data without altering the current state. I’ll start by capturing disk snapshots and logs, then analyze Magento core, generated files, database configs, cron jobs, and API/admin access for persistence points. I’ll also review AWS CloudTrail and Cloudflare logs to identify the initial breach and firewall gaps. Before any cleanup, I’ll isolate compromised credentials and rotate keys to prevent further access. Hardening will include Magento patches, strong ACL policies, and Cloudflare WAF tuning. I’ll verify the checkout flow through staged testing before reopening. Also, I will investigate your recurring OOM and Elasticsearch performance, which could relate to the compromise or misconfiguration. Do you have WAF logs or AWS GuardDuty alerts available? That data can speed identifying the attack vector. I’m ready to start immediately and will provide a detailed report covering root cause, infection timeline, and a clear remediation plan once cleanup is complete.
€250 EUR in 7 days
5.9
5.9

Hi, I can assist immediately with your Magento 2 production security incident and perform a proper forensic investigation rather than simply removing visible malware. My first priority will be **evidence preservation before making production changes**. I’ll secure/verify AWS SSH access, take appropriate snapshots/backups, preserve relevant logs and timestamps, and establish the current indicators of compromise. I’ll then investigate Magento core/custom modules, static/generated content, database-injected JavaScript, configuration, cron jobs, Admin/API accounts, filesystem changes, AWS/Linux logs, and persistence mechanisms to identify the compromise source and full scope. After containment, I can safely remove malicious code, rotate/revoke affected credentials, harden Magento/AWS/Cloudflare, and thoroughly validate checkout before reopening it. I can also investigate the recurring PHP/MySQL/Varnish/Elasticsearch OOM and performance issues. You will receive a technical incident report covering findings, root cause, affected components, remediation performed, and recommended preventative measures. I’m available to start immediately. Best regards, Ali
€500 EUR in 7 days
6.1
6.1

Hello, I can urgently handle your Magento 2 security incident with a focus on forensics, root-cause analysis and complete remediation, not just deleting infected files. I don’t hold an Adobe Commerce/Magento certification, but I have strong hands-on experience with Magento 2, AWS EC2, Linux, PHP, MySQL, Elasticsearch, Varnish, Nginx and Cloudflare. My first step will be preserving evidence through snapshots/log backups before making production changes. I’ll investigate the initial entry point, persistence, malicious JS/skimmer, modified files, DB/configuration, cron jobs, Admin/API access and server logs. After identifying the full attack path, I’ll safely clean the environment and rotate/revoke compromised credentials and keys. I’ll then harden Magento/AWS/Cloudflare and thoroughly validate storefront and checkout before reopening. I can also investigate the recurring OOM, Varnish, PHP, MySQL and Elasticsearch issues. Finally, I’ll provide a clear technical report covering findings, root cause, remediation and prevention. Available to start immediately.
€250 EUR in 5 days
5.6
5.6

Hi there, I see you're dealing with a Magento 2 security incident, which can be quite stressful. Your main goal is to effectively respond to the malware threat and secure your AWS environment. With over 10 years of experience in PHP and web security, I have a strong background in incident response and have successfully handled similar situations. Let’s work together to ensure your site is secure and functioning smoothly again. Best,
€500 EUR in 4 days
6.0
6.0

==== Hi - Truong here ==== "MAGENTO 2 MALWARE / CARD SKIMMER INCIDENT RESPONSE" — you need the compromise contained and its persistence found before cleanup. I’d first preserve the EC2 state, relevant logs, Magento files/database and Cloudflare evidence before changing production. Then I’d trace the malicious checkout requests, inspect cron/Admin/API access and modified code, identify persistence, rotate exposed credentials, and only then clean and harden the environment. I’d also check the OOM/Varnish/PHP/MySQL/Elasticsearch issues separately so the incident response does not hide an underlying server problem. Can you provide the current EC2 access situation and confirm whether an EBS snapshot has already been taken? Looking forward to work with you.
€250 EUR in 1 day
4.8
4.8

Hi, I can see this is an active Magento 2 security incident, not a routine cleanup. The priority is to contain the skimmer, preserve evidence, and trace how it entered and persists before anything is modified. I’ve handled Magento 2 and Adobe Commerce security work, including malware cleanup, compromised admin access, and server-side investigation across AWS/Linux environments. My focus is on root cause, not just removing infected generated files. My first steps would be to secure access, snapshot logs and key files, review Magento code, cron, database, admin/API users, static/generated content, and Cloudflare/AWS layers, then map persistence and exfiltration paths. After that I would clean, rotate credentials, harden the stack, and verify checkout is safe before reopening. I’m available immediately and can start with a forensic-safe assessment right away. Best regards, Gabriel
€250 EUR in 7 days
4.2
4.2

It’s clear that you are facing a critical security incident that demands immediate and expert attention. I have extensive experience dealing with similar Magento 2 security breaches, having successfully managed multiple incidents involving malware and card skimmers. My goal is to ensure your environment is fully secured while preserving essential forensic evidence for future analysis. I understand the urgency of establishing secure SSH access to AWS and performing a thorough inspection of your Magento setup to identify vulnerabilities. My background includes Magento certification, AWS security expertise, and a strong focus on performance, security, and user experience. Could we discuss the specific steps you envision taking to safeguard your platform and restore operations? Best regards, Foraxis
€550 EUR in 7 days
2.6
2.6

Montijo, Portugal
Payment method verified
Member since Aug 11, 2015
€8-30 EUR
€10 EUR
€30-250 EUR
€30-250 EUR
€8-30 EUR
$250-750 USD
₹12500-37500 INR
₹12500-37500 INR
€250-750 EUR
₹750-1250 INR / hour
$15-25 USD / hour
$15-25 USD / hour
₹37500-75000 INR
₹1500-12500 INR
$30-250 USD
$10-30 USD
$8-15 USD / hour
$250-750 USD
$3000-5000 USD
$250-750 USD
₹600-1500 INR
₹12500-37500 INR
$10-15 CAD
$10-30 USD
$10-30 USD